PT-2009-1549 · Php · Phpcrs

Pepelux

·

Publicado

2009-02-06

·

Atualizado

2018-10-11

·

CVE-2008-6074

CVSS v2.0

5.1

Média

VetorAV:N/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions phpcrs versions 2.06 and earlier
Description The issue allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the importFunction parameter when magic quotes gpc is disabled. This can be exploited by sending a malicious request to the /frame.php endpoint.
Recommendations For phpcrs versions 2.06 and earlier, consider disabling the importFunction parameter in the frame.php file until a patch is available. Additionally, enabling magic quotes gpc may help mitigate the risk of exploitation.

Exploit

Correção

Path traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-6074

Produtos afetados

Phpcrs